« List of all CVEs

CVE-2012-6711

Published: 6/18/2019 Last updated: 8/6/2024 Reserved: 6/18/2019

A heap-based buffer overflow exists in GNU Bash before 4.3 when wide characters, not supported by the current locale set in the LC_CTYPE environment variable, are printed through the echo built-in function. A local attacker, who can provide data to print through the "echo -e" built-in function, may use this flaw to crash a script or execute code with the privileges of the bash process. This occurs because ansicstr() in lib/sh/strtrans.c mishandles u32cconv().

CNA assigner: mitre (8254265b-2729-46b6-b9e3-3dfca2d5bfca) Requested by: n/a

Metrics

Version Score Severity Vector String
3.0 7 High CVSS:3.0/AC:H/AV:L/A:H/C:H/I:H/PR:L/S:U/UI:N

Opam packages affected (1)

conf-bash

Products affected (1)

Product Vendor Version
n/a n/a n/a

References (12)